Forum Discussion
Restrict Owners
- Nov 24, 2021
There will always need to someone who has enough permissions to help fix things if things go south. The best practice is the use of named admin accounts, this way you can give de admin permissions to the named admin account and not your personal account.
On your personal account you will just see the data that you are allowed to see but on the named admin account you could see everything and help where needed.
The reason you still see the library after removing the owner permissions is because you are set as the site collection administrator which is a higher permission then the owner group.
There will always need to someone who has enough permissions to help fix things if things go south. The best practice is the use of named admin accounts, this way you can give de admin permissions to the named admin account and not your personal account.
On your personal account you will just see the data that you are allowed to see but on the named admin account you could see everything and help where needed.
The reason you still see the library after removing the owner permissions is because you are set as the site collection administrator which is a higher permission then the owner group.
- Ben LeachNov 24, 2021Copper ContributorAs mentioned earlier in this thread, you really don't want to lock away areas of a site from owners as it is a supportability issue, and again as has been said, there is always a role that will have access to everything in the site (known as the Site Collection Administrator).
If you have Business Premium or E3 licences, the best approach is to configure Sensitivity Labels within the Compliance Centre of Microsoft 365 Admin. You can define the label, configure it as requiring encryption and control who can access the content, assigning it to specific departments via security or M365 groups. Once you have created the label, deploy it to the users that you want to be able to use it via a Label Policy. The advantage of this approach is that even if the content is downloaded and shared either internally or outside the organisation, the protection will still be applied and doesn't rely on having to set (and remember) passwords